Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2019-01-14 CVE-2018-16888 Improper Privilege Management vulnerability in multiple products
It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes.
4.7
2019-01-09 CVE-2018-0671 Improper Privilege Management vulnerability in MNC Inplc-Rt 3.08
Privilege escalation vulnerability in INplc-RT 3.08 and earlier allows an attacker with administrator rights to execute arbitrary code on the Windows system via unspecified vectors.
local
low complexity
mnc CWE-269
6.7
2018-12-28 CVE-2018-1000624 Improper Privilege Management vulnerability in Battelle V2I HUB 2.5.1
Battelle V2I Hub 2.5.1 is vulnerable to a denial of service, caused by the failure to restrict access to a sensitive functionality.
network
low complexity
battelle CWE-269
7.5
2018-12-21 CVE-2018-20193 Improper Privilege Management vulnerability in Pulsesecure Secure Access Series SSL VPN Sa-4000 4.2/5.1R5
Certain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by Pulse Secure, LLC) allow privilege escalation, as demonstrated by Secure Access SSL VPN SA-4000 5.1R5 (build 9627) 4.2 Release (build 7631).
network
low complexity
pulsesecure CWE-269
8.8
2018-12-20 CVE-2018-15331 Improper Privilege Management vulnerability in F5 Big-Ip Application Acceleration Manager
On BIG-IP AAM 13.0.0 or 12.1.0-12.1.3.7, the dcdb_convert utility used by BIG-IP AAM fails to drop group permissions when executing helper scripts, which could be used to leverage attacks against the BIG-IP system.
local
low complexity
f5 CWE-269
7.8
2018-12-20 CVE-2018-11965 Improper Privilege Management vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Anyone can execute proptrigger.sh which will lead to change in properties.
local
low complexity
google CWE-269
7.8
2018-12-20 CVE-2018-1973 Improper Privilege Management vulnerability in IBM API Connect
IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level access through the members functionality.
network
low complexity
ibm CWE-269
7.2
2018-12-12 CVE-2018-8619 Improper Privilege Management vulnerability in Microsoft Internet Explorer 10/11/9
A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
network
high complexity
microsoft CWE-269
7.5
2018-12-12 CVE-2018-10143 Improper Privilege Management vulnerability in Paloaltonetworks Expedition 1.0.107
The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level commands on the device hosting this service/application.
network
low complexity
paloaltonetworks CWE-269
critical
9.8
2018-12-11 CVE-2018-18344 Improper Privilege Management vulnerability in multiple products
Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote attacker with control of an installed extension to access files on the local file system via a crafted Chrome Extension.
network
low complexity
google debian redhat CWE-269
6.5